@ledgerhq/hw-app-celo
Ledger Hardware Wallet Celo Application API
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@celo/contractkit | AI (dependencies): @celo/contractkit is the official Celo SDK and a legitimate dependency for a Celo hardware wallet app; this finding is a stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): LedgerHQ publishes via CI bot without Sigstore provenance; this is consistent across their package ecosystem and not a security concern. | ai | |
| phantom-deps | phantom-dep:@ledgerhq/hw-transport | AI (phantom-deps): Same-org scope package; phantom detection is a false positive for monorepo packages where deps appear in config/type files rather than direct imports. | ai | |
| phantom-deps | phantom-dep:@celo/utils | AI (phantom-deps): Referenced in config files per the finding; typical for TypeScript monorepo packages where deps appear in tsconfig or jest config rather than direct source imports. | ai | |
| phantom-deps | phantom-dep:@celo/contractkit | AI (phantom-deps): Referenced in config files; false positive for monorepo build tooling patterns. | ai | |
| phantom-deps | phantom-dep:rlp | AI (phantom-deps): Referenced in config files; legitimate dependency for RLP encoding in Celo/Ethereum transaction handling. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Referenced in config files; common utility dependency used in build/test tooling. | ai | |
| phantom-deps | phantom-dep:bip32-path | AI (phantom-deps): Referenced in config files; legitimate dependency for BIP32 HD wallet path handling in a hardware wallet package. | ai | |
| phantom-deps | phantom-dep:@celo/wallet-ledger | AI (phantom-deps): Referenced in config files; false positive for monorepo build tooling patterns. | ai | |
| phantom-deps | phantom-dep:@ledgerhq/errors | AI (phantom-deps): Same-org scope package in a monorepo; phantom-dep detection is a known false positive for @ledgerhq/* packages used in type definitions or re-exports. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Buffer.from(rawTxHex, 'hex') is standard hex decoding of blockchain transaction data in a hardware wallet library. Not obfuscated or malicious. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 7.1.2 | 7 / 10 | |
| 7.1.1 | 7 / 10 | |
| 7.1.0 | 7 / 10 | |
| 7.0.2 | 13 / 10 | |
| 7.0.1 | 13 / 10 | |
| 7.0.0 | 13 / 10 | |
| 6.40.0 | 11 / 10 | |
| 6.39.2 | 11 / 10 | |
| 6.39.1 | 11 / 10 | |
| 6.39.0 | 11 / 10 | |
| 6.38.0 | 11 / 10 | |
| 6.37.6 | 11 / 10 | |
| 6.37.5 | 11 / 10 | |
| 6.37.4 | 11 / 10 | |
| 6.37.3 | 11 / 10 | |
| 6.37.2 | 11 / 10 | |
| 6.37.1 | 11 / 10 | |
| 6.37.0 | 11 / 10 | |
| 6.36.0 | 11 / 9 | |
| 6.35.7 | 11 / 9 | |
| 6.35.6 | 11 / 9 | |
| 6.35.5 | 11 / 9 | |
| 6.35.4 | 11 / 9 | |
| 6.35.3 | 11 / 9 | |
| 6.35.2 | 11 / 9 |
v7.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.40.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.39.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.39.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v6.35.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.